Data processing

What you need for your record of processing.

When you use ClickCheck, we process data on your behalf. This page covers what you need to document that properly.

Roles

Your organisation is the data controller: you decide which rules exist, for which employees and with what retention period. ClickCheck is the processor and only processes the data to deliver the service.

Which data

  • Account details of dashboard users: name, email address, role, language.
  • Linked devices: a device name, browser and time of last contact.
  • Events: which rule was triggered, on which website, when, by whom and what was chosen.
  • Approval requests: requester, approver, amount, reason, decision and time.
  • Audit data: who created, changed or published rules.

Which data not

Page content, browsing history, keystrokes, form contents, screenshots and text pasted into AI tools. None of it is sent to ClickCheck.

Purpose and retention

The data is only used to run rules, handle approvals and give you insight and an audit trail. Events are deleted automatically after the period you choose (90, 180 or 365 days).

Sub-processors

We’ll publish the list of sub-processors here before paid plans start. If you need it now, get in touch.

The agreement itself

We sign a data processing agreement with every organisation that uses ClickCheck for business. We’ll make the document available on this page and in the dashboard. Need it now? Get in touch.

Security measures

The technical and organisational measures are described on the security page: minimal data, local detection, per-device keys, single-use approvals and separated customer data.